And on the "official statements" part, it's kind of naive to expect that they (UIDAI) would put out any statement given that in the past they have
- Not acknowledged security issues or made any efforts to do their own investigation in spite of the numerous reports
- Turned hostile towards entities who have exposed or reported weaknesses instead of rewarding them and plugging the loopholes
here you go
NDTV
https://gadgets.ndtv.com/internet/news/aadhaar-software-patc...
It is on the front page.
It takes mainstream sources a while to react to news. In 24-48 hours, all mainstream newspapers will have the news.
[1]https://en.wikipedia.org/wiki/Radia_tapes_controversy#Media_...
"The patch lets a user bypass critical security features such as biometric authentication of enrolment operators to generate unauthorised Aadhaar numbers.
The patch disables the enrolment software's in-built GPS security feature (used to identify the physical location of every enrolment centre), which means anyone anywhere in the world — say, Beijing, Karachi or Kabul — can use the software to enrol users.
The patch reduces the sensitivity of the enrolment software's iris-recognition system, making it easier to spoof the software with a photograph of a registered operator, rather than requiring the operator to be present in person."
https://thewire.in/government/data-breach-aadhaar-details-gr...